CVE-2026-20254: Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server when a higher-privileged user views it, bypassing the external content restriction through a Cascading Style Sheets (CSS) injection.<br><br>The Trusted Domains security check does not fully validate inline style attribute values, which can allow for outbound requests to untrusted domains and credential exfiltration when a victim views a crafted dashboard.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.4 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.15 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.23 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 9.3.2411.132
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20254?
CVE-2026-20254 has a medium severity rating of 5.7.
How does CVE-2026-20254 impact Splunk Enterprise users?
CVE-2026-20254 allows a low-privileged user to exploit a vulnerability that can lead to information disclosure through external content restriction bypass.
What are the affected versions in CVE-2026-20254?
CVE-2026-20254 affects Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, as well as several versions of Splunk Cloud Platform.
How do I mitigate CVE-2026-20254?
Mitigation for CVE-2026-20254 involves upgrading to the patched versions of Splunk Enterprise or Splunk Cloud Platform as specified in the advisory.
Who is most at risk from CVE-2026-20254?
Users with low privileges who do not hold the 'admin' or 'power' roles in Splunk are at a higher risk from CVE-2026-20254.